HIPAA Compliance & Business Associate Agreement

Empower Cove is designed to comply with the Health Insurance Portability and Accountability Act (HIPAA) and supports the secure handling of Protected Health Information (PHI). However, HIPAA compliance is a shared responsibility between you and Empower Cove.

1. Business Associate Agreement (BAA)

By using Empower Cove to store, process, or transmit PHI, you are entering into a Business Associate Agreement with Empower Cove. A formal BAA document is available upon request and must be signed before using the Service with PHI.

Key provisions of our BAA:

  • Empower Cove will safeguard all PHI using industry-standard encryption and security measures
  • PHI will only be used for purposes authorized by you or as required by law
  • Empower Cove will not share PHI with unauthorized third parties
  • Empower Cove will immediately notify you of any data breach or unauthorized access
  • Empower Cove maintains comprehensive audit logs and security monitoring
  • All subcontractors who have access to PHI have signed their own Business Associate Agreements

2. Your HIPAA Responsibilities

To maintain HIPAA compliance, you (the Covered Entity or Hybrid Entity) must:

  • Ensure only authorized staff access client data
  • Use strong passwords and multi-factor authentication
  • Maintain physical and technical safeguards at your practice location
  • Implement an access control policy limiting who can view PHI
  • Keep your Empower Cove software and devices updated
  • Conduct regular security training for all staff
  • Immediately report any suspected data breaches to Empower Cove
  • Sign Business Associate Agreements with your own vendors and subcontractors

3. Data Encryption & Security

In Transit: All data transmitted to and from Empower Cove is encrypted using TLS 1.2 or higher.

At Rest: All PHI stored in Empower Cove databases is encrypted using AES-256 encryption.

Access Controls: Access to client data is restricted based on role-based permissions. Only authorized users can view specific records.

Audit Logging: All access to PHI is logged with timestamps and user identifiers for HIPAA compliance auditing.

4. Data Breach Notification

If we detect or suspect a data breach involving PHI, we will:

  • Notify you immediately (within 24 hours)
  • Provide details of what data was potentially compromised
  • Assist you in complying with HIPAA breach notification requirements
  • Conduct a thorough investigation and remediation

5. HIPAA Limitations

You acknowledge that:

  • Empower Cove cannot guarantee 100% security or prevent all unauthorized access
  • HIPAA compliance requires your active participation and proper use of the platform
  • You remain responsible for the confidentiality and security of PHI within your practice
  • Use of non-secure communication methods (email, text) may violate HIPAA, regardless of Empower Cove's security measures

6. Business Associate Agreement Contact

To request a formal Business Associate Agreement or for HIPAA-related questions, contact:

Empower Cove Compliance Team

Email: support@empowercove.com